Re: Intrusion Detection Systems

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



John Hinton <webmaster@xxxxxxxx> wrote:

>>
I did look at snort and actually some people run both snort and OSSEC. I
don't remember the reasons.
<<

Simply put, they're different things. Snort is a network IDS which examines
network traffic packets, looking for the signatures of various attacks.
OSSEC is host IDS which monitors logs for evidence of attacks or misuse on
a host OS. In many installations, you need them both.

Best,

--- Les Bell, RHCE, CISSP
[http://www.lesbell.com.au]
Tel: +61 2 9451 1144
FreeWorldDialup: 800909


_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos

[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux